Legal
Effective July 22, 2026
This policy describes what Cointrol (cointrol.xyz) collects, why, and the choices you have. The short version: we collect the minimum needed to run accounts, subscriptions and the newsletter, we don’t sell personal data, and you can use most of the site without an account at all.
Account data — email address, display name, a hashed password, your subscription tier, and the watchlist and portfolio entries you choose to sync to your account.
Newsletter and contact — the email address you subscribe with, and the name, email and message you send through the contact form.
Guest mode— without an account, your watchlist and portfolio live only in your browser’s localStorage and are never sent to our servers.
Technical logs — standard server logs (IP address, user agent, requested pages) kept briefly for security, rate limiting and debugging.
Subscriptions are processed by Stripe. Your card details go directly to Stripe and never touch our servers; we store only your Stripe customer and subscription identifiers and the resulting tier. Stripe’s own privacy policy applies to payment processing.
When you look up a wallet address, the address is forwarded to Moralis to fetch public on-chain balances. Wallet addresses are public blockchain data; we do not link looked-up addresses to your account or store the results beyond short-lived caching.
We share data only with the processors that run the service:
We do not sell personal data or share it with advertisers.
We use a single first-party, HTTP-only session cookie to keep you logged in. There are no third-party advertising or tracking cookies.
Account data is kept while your account is active. You can update your watchlist, portfolio and name from the site, unsubscribe from the newsletter at any time, and request account deletion or an export of your data via the contact page— we’ll action it within 30 days. Depending on where you live (e.g. GDPR regions), you may also have rights to access, correct, restrict or port your data.
Passwords are stored hashed, sessions use HTTP-only cookies, database access is restricted, and payment data never reaches our infrastructure. No system is perfectly secure — if we learn of a breach affecting your data we will notify you.
We’ll post any changes to this policy here and update the effective date. For privacy questions, use the contact page. See also our Terms of Service.